TISAX® is how automotive suppliers demonstrate their information security. When an OEM or a larger supplier asks for that proof, you go through an assessment and receive a label. This article covers how the framework is structured, where the work actually sits, and which parts of it can be automated.
Who requires TISAX®
TISAX® was established by the German Association of the Automotive Industry (VDA) and is administered by the ENX Association.
Most European OEMs require TISAX® of their direct suppliers, and those suppliers require it of their own. The obligation travels several tiers down a supply chain, so it can reach you without an OEM ever contacting you directly.
What TISAX® is for
TISAX® standardizes information security assessment against the VDA ISA catalog, which is itself derived from ISO 27001.
The point of the exchange is mutual recognition. Once you complete an assessment, the result is shared with your customers through the ENX portal, so you do not repeat a full security audit for every OEM that asks. Suppliers who complete an assessment receive a TISAX® label, valid for three years.
Assessment levels and objectives
TISAX® has three assessment levels with increasing requirements:
- AL1: self-assessment, rarely accepted by OEMs
- AL2: assessment for high protection needs
- AL3: assessment for very high protection needs, normally required for prototype protection
There are also three main assessment objectives:
- Information security: core requirements based on ISO 27001
- Prototype protection: measures protecting prototype vehicles and components
- Data protection: requirements for handling personal data under the GDPR
Each level and each objective brings its own evidence requirements, and they overlap. The same control can fall under more than one objective, with a different depth expected each time. This is where manual tracking starts to strain.
The three problems with managing TISAX® manually
Whatever the size of the supplier, manual management runs into the same three problems.
The first: evidence has to be current, not merely available. An assessment checks whether your controls were operating during the period under review. A screenshot taken eight months ago proves what was true eight months ago.
The second: the evidence does not sit in one place. Access logs are in your identity provider, training completions in your HR system, device inventories in your endpoint tool, supplier contracts on legal's drive. Someone has to open each of those systems, export what is needed, and keep track of which version they exported.
The third: TISAX® does not end. Labels expire, your scope shifts as you win customers with different protection needs, and controls drift because your systems change. A folder that was accurate on assessment day is out of date within months.
What can be automated
Evidence collection and management
An automation platform can connect directly to your systems and pull evidence, rather than having someone export it by hand. It standardizes the formats so assessors accept them, and it keeps a history you can use to demonstrate that a control operated continuously rather than on the day someone checked.
Cross-functional workflows
A TISAX® implementation pulls in IT, engineering, HR, legal, procurement and production. Coordinating between those functions is often the slowest part of the project.
Automation helps here through:
- role-based assignment of responsibilities
- automatic task distribution and reminders
- central progress tracking you can read at any time
Prototype protection
AL3 assessments impose particularly strict prototype protection requirements. What is asked for is not only security technology but complete traceability of access, use and handling across the development lifecycle.
In practice: for any prototype file or physical part, you need to be able to say who accessed it, when, and under whose approval. If finding that out takes three phone calls, it is not traceability.
How suppliers go about it
From manual to automated
Suppliers who start out managing TISAX® manually and later automate tend to follow the same order:
- Process analysis: document the existing manual processes
- Targeted automation: identify the expensive, repeatable processes to start with
- Gradual extension: evidence collection first, then the rest
Automating prototype protection
Suppliers whose scope includes prototype protection at AL3 face a narrower and harder problem than general information security. The approach that holds up focuses on three things:
- Continuous monitoring of access to prototype data and how it is used
- Digital approval workflows for access requests
- Logging of all prototype-related activity
Your TISAX® automation roadmap
Step 1: assess your requirements and current state
Start by working out which assessment level and which objectives apply to you.
The most common and most expensive mistake at this stage is scoping too wide. Implementing controls beyond what your customers actually require costs real effort and earns you no additional label.
Document where you stand on:
- implementation status of your security controls
- evidence collection processes
- relevant systems and data repositories
- cross-departmental workflows
Step 2: prioritize what to automate
Start with the tasks that recur and have clear inputs and outputs. Those automate cleanly. Tasks that require professional judgment do not, and trying to tackle those first is why automation projects stall.
The usual candidates:
- evidence collection from your security and IT management tools
- tracking and documenting policy acceptance
- access control monitoring and logging
Step 3: choose technologies and partners
Generic compliance tooling usually covers the information security objective adequately, then falls short on prototype protection, because there is no equivalent in ISO 27001. Ask about it specifically.
Other criteria:
- pre-built TISAX® control catalogs and assessment templates
- integrations with the security and IT tools you already run
- supplier management features, if you have to assess your own supply chain
Step 4: roll out in phases
Do not automate everything at once. A sequence that works:
- Foundation: core platform and document repository
- Evidence collection: connect the main systems
- Workflows: cross-departmental processes and approvals
- Extension: analytics and continuous monitoring
Conclusion
Automation is an investment. The return shows up as less scrambling in the weeks before an assessment, and as fewer controls that quietly lapse between them.
If your scope widens because a new customer arrives with a higher protection need, you extend an existing system rather than starting over.
Kertos automates the evidence work behind TISAX®, ISO 27001 and the GDPR on one platform. Book a time if you want to see what that looks like for your scope.





